PULSE
FEED
vulnKEV agrega CVE-2026-67279 — MikroTik / RouterOSvulnKEV agrega CVE-2026-65660 — Microsoft / SharePointvulnKEV agrega CVE-2026-5430 — WSO2 / Multiple ProductsvulnKEV agrega CVE-2026-71362 — Adobe / Commerce and Magento vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-67279 — MikroTik / RouterOSvulnKEV agrega CVE-2026-65660 — Microsoft / SharePointvulnKEV agrega CVE-2026-5430 — WSO2 / Multiple ProductsvulnKEV agrega CVE-2026-71362 — Adobe / Commerce and Magento vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services Engine
Kalir Brief · Item25 September 2026 · 19:04 UTC
BRIEFLeakhighP48

Unauthenticated GCP MySQL database exposing PII leaked

Detected25 September 2026 · 19:04 UTC
Why it matters

A freshly found MySQL database on Google Cloud Platform was left without authentication, exposing PII from a Korean exam dataset and a Saudi loan dataset, with signs of ransomware involvement. Open cloud databases let attackers bulk-scrape personal and financial records. Affected teams should force credential rotation and confirm the exposure is closed.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score48
Detected25 September 2026 · 19:04 UTC
Related items6
Leak● 52
Filtración de 6,5 millones de registros de robo (URL:login:pass)A 6.5 million stealer-log set in URL:login:password format was posted for free roughly an hour before capture. These logs originate from infostealer malware and contain live corporate and consumer credentials usable for account takeover and session hijacking. Defenders should feed it into credential-monitoring to detect exposed employee or customer logins.
18m
Leak● 66
Base de datos del seguro de salud de Corea del Sur a la ventaA seller is offering a South Korean health-insurance database with around 39 million records, a large-scale PII/PHI leak of a national insurer. Health data at this scale enables identity theft, medical fraud and targeted phishing against millions of policyholders. The sale itself is a strong indicator that the data may be redistributed or weaponized soon.
18m
Leak● 82
Filtración de 10 millones de casos del FBIA poster claims to have leaked a database containing roughly 10 million FBI case records, posted within minutes. If authentic, this is a high-impact exposure of US federal law-enforcement data with investigative, victim and informant details. Defenders should treat it as a priority verification item despite the region falling outside LATAM.
18m
Leak● 60
Filtración de datos del Centro Nacional de Bomberos de EE.UU.A threat actor published a downloadable dump of data allegedly taken from the US National Interagency Fire Center (NIFC), a federal wildfire-response agency. Though outside Latin America, a government breach can fuel phishing, credential reuse and follow-on intrusion. Defenders should verify scope and watch for reuse of the data.
1h
Leak● 48
Venta de 82,9 millones de credenciales francesasA seller offers an 82.9 million record email:password dump, allegedly extracted from a large credential-stealer collection, for 500 USDT. Even if recycled from older stealer logs, the sheer volume enables credential-stuffing and targeted phishing against French users and organizations. Defenders should monitor for reuse of these credentials and enforce MFA.
2h
Leak● 68
Base de datos de 13M de business.adobe.com a la ventaA seller is offering a business.adobe.com dataset of roughly 13 million records and 832 GB, posted on DarkForums very recently. Adobe is a major SaaS and identity provider, so leaked corporate data could fuel targeted phishing and account abuse. The data may be recycled from older Adobe breaches, so verify freshness before alerting.
2h